Threats

Clop Leak Site Hijacked by ShinyHunters, Docker Botnet Targets AI Keys, Water Utilities Exposed via Infostealer Logs

September 25, 2026 16:00 · 12 min read
Clop Leak Site Hijacked by ShinyHunters, Docker Botnet Targets AI Keys, Water Utilities Exposed via Infostealer Logs

Clop Leak Site Taken Over in ShinyHunters Grudge Match

The cybercrime group ShinyHunters has defaced the Tor-based data leak site operated by the Cl0p ransomware gang, claiming to have stolen server logs, source code, and the private keys for Clop’s onion service. According to ShinyHunters, the breach was motivated by retaliation for threats allegedly made by a Clop representative during a feud originating from the Clop Oracle E-Business Suite extortion campaign. The group demanded an eight-figure payment and a public apology, warning that it would expose companies suspected of having paid Clop during that campaign if its demands were not met.

BragJack Flaws Allow Extension Hijack of Browser AI Assistants

Researchers at Forever disclosed a set of vulnerabilities named BragJack that enable a malicious browser extension to seize control of built-in AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and the Claude in Chrome extension. The flaw stems from the assistants’ implicit trust in commands originating from specific web pages, which a compromised extension can exploit by injecting scripts or manipulating network traffic. Once hijacked, the assistant can be forced to execute prompts without user interaction, potentially allowing attackers to read emails, access local files, capture screenshots, or activate the camera and microphone. Vendors awarded bounties ranging from $600 to $7,000 for the responsibly disclosed findings.

Malicious Go Implant Targets AI Agent Tooling via MemTensor Packages

Attackers published trojanized versions of MemTensor’s MemOS packages on npm and PyPI, including a memory plugin for the OpenClaw AI agent framework. These packages contain a previously undetected Go-based implant named sckit, which does not execute during installation but activates when the Python library is imported or the npm plugin is used. Upon activation, the implant scans for sensitive data such as npm, PyPI, GitHub, AWS, and Hugging Face credentials and includes templates for self-propagation via npm, PyPI, and GitHub Actions. While no active propagation has been observed, researchers from Aikido, StepSecurity, and Semgrep have analyzed the malware’s capabilities.

AI Relay Networks Enable Chinese Users to Access Western Frontier Models

Team Cymru identified nearly 11,000 servers running the Claude Relay Service or its successor, sub2api — open-source gateways that pool AI accounts to allow multiple users to share them while concealing individual identities from model providers. In one U.S.-hosted cluster, over 4,000 IP addresses from China and Hong Kong connected to 304 relays that also accessed endpoints for OpenAI, Anthropic, xAI, and Google. These regions are typically blocked by major AI providers due to policy restrictions, making the relay network a method to circumvent geographic access controls.

Infostealer Logs Reveal Remote-Access Keys in US Water Sector

SpyCloud analyzed stolen identity data linked to 10,000 U.S. water and wastewater utilities and their technology vendors, discovering active infostealer exposure at 1,787 organizations. Among these, credentials for operational technology (OT) or remote-access systems were found at 258 entities. In a notable case, malware on a single device at an advanced-metering technology provider harvested saved logins for approximately 167 utility metering portals. Exposed credentials at the utilities themselves primarily involved remote-administration tools such as TeamViewer, SonicWall, and Fortinet management interfaces. SpyCloud emphasized that the findings indicate potential access paths, not confirmed breaches.

CLOSEDQUORUM Implant Uses LLMs for Autonomous Command-and-Control

Cisco Talos analyzed CLOSEDQUORUM, a Go-based Windows implant believed to be the first publicly documented malware to delegate command-and-control decisions to commercial large language models (LLMs). The implant can query up to four models — DeepSeek, Qwen, Mistral, and Gemini — to vote on actions such as stealing credentials, injecting code, or establishing persistence. The winning decision is executed, and stolen data including LSASS dumps, browser passwords, and cryptocurrency wallet information is transmitted to the operator via Discord. Although no confirmed wild usage has been verified, development builds show customizable configurations, and the public release contains placeholder API keys.

Canonical Accelerates Ubuntu Kernel Updates with Weekly Cycle

Canonical has overhauled Ubuntu’s kernel update process by merging its previous four-week regular and two-week security Stable Release Update (SRU) cycles into a single two-week cycle. Due to the overlapping schedule, a new kernel will now be released every week. The change responds to a surge in CVE volume driven by AI-assisted bug discovery and the upstream kernel community’s role as its own CVE Numbering Authority, which has led to thousands of new identifiers. Users seeking faster access to fixes can test release candidates from the -proposed repository prior to full certification, and Canonical aims to deliver workarounds or hardening guidance within 24 to 48 hours of public vulnerability disclosure.

Pre-Auth TDengine Flaw Enables Remote Crash via RPC Port

Ridge Security disclosed CVE-2026-42542, a high-severity vulnerability in TDengine, a time-series database widely used in industrial telemetry, energy, utilities, and IoT systems. The flaw allows an unauthenticated attacker to crash the server by sending a single malformed packet to its RPC port. It results from an integer underflow in message parsing that occurs before authentication, triggering a heap buffer overflow. While researchers confirmed only denial-of-service outcomes, they caution that the underlying memory corruption could pose broader risks. Versions 3.4.0.0 through 3.4.1.5 are affected, with version 3.4.1.6 containing the fix.

Android Banking Trojan RemControl Leverages AI-Generated Phishing Overlays

Group-IB identified RemControl, a new Android banking trojan distributed as malware-as-a-service (MaaS) through counterfeit Google Play pages for the TVTap IPTV app. It targets customers of over 30 banks across Western Europe, the Middle East, and Canada. After gaining Accessibility permissions, the trojan displays phishing overlays on legitimate banking apps, records screen activity, logs keystrokes, and grants attackers full remote control of the device. Analysis revealed that certain components of the platform were likely developed using an AI assistant misled into believing it was creating a quiz and parental monitoring application, with one phishing overlay containing a full AI-generated response.

Docker Botnet CARBONATO Prioritizes Theft of AI API Keys

ThreatDown detailed CARBONATO, a botnet that compromises exposed Docker daemons listening on unauthenticated port 2375 and scans adjacent networks every five minutes to propagate. On each infected host, it deploys Hermes Agent — a legitimate open-source AI agent framework — and replaces its persona file with malicious instructions to follow Telegram-based operator commands, maintain persistence, and harvest credentials. The botnet explicitly ranks AI API keys as its primary target, surpassing other credential types. The operation was uncovered via an exposed, unauthenticated Docker registry, with linguistic, temporal, and infrastructure evidence pointing to operators based in Costa Rica.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free